Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an authenticated administrator could leverage the Migrate Server feature to obtain root privileges on the underlying XI host. By abusing the migration workflow, an admin-level attacker could execute actions outside the intended security scope of the application, resulting in full control of the operating system.
CVSS
No CVSS.
References
Configurations
No configuration.
History
03 Nov 2025, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-03 22:16
Updated : 2025-11-04 15:41
NVD link : CVE-2024-13997
Mitre link : CVE-2024-13997
CVE.ORG link : CVE-2024-13997
JSON object : View
Products Affected
No product.
CWE
CWE-269
Improper Privilege Management
